The release of Whonix version 17.4 is now available, aimed at providing guaranteed anonymity, security, and protection of personal information. This distribution is based on Debian GNU/Linux and uses Tor for anonymity. The project's developments are distributed under the GPLv3 license. Prepared virtual machine images in ova format for VirtualBox (2.3 GB with Xfce and 1.5 GB console) are available for download and can be converted for use with the KVM hypervisor.
A key feature of Whonix is the separation of the distribution into two separately executable components — Whonix-Gateway with a network gateway implementation for anonymous communications and Whonix-Workstation with a desktop environment. The components represent separate system environments, provided within a single boot image and launched in different virtual machines. Network access from the Whonix-Workstation environment is only via the Whonix-Gateway, isolating the working environment from direct interaction with the outside world and allowing only the use of fake network addresses. This approach protects the user from the leakage of real an IP address in the event of a browser hack or exploitation of a vulnerability that gives the attacker root access to the system.
Hacking Whonix-Workstation would allow the attacker to obtain only dummy network parameters, as the real IP and DNS parameters are hidden behind the boundary of the network gateway operating on the basis of Whonix-Gateway, which directs traffic solely through Tor. It should be noted that Whonix components are designed to run as guest systems, meaning there is a possibility of exploiting critical 0-day vulnerabilities in virtualization platforms that could grant access to the host system. Therefore, it is not recommended to run Whonix-Workstation on the same computer as Whonix-Gateway.
In Whonix-Workstation, the default user environment is Xfce. The distribution includes programs such as VLC, Tor Browser, Pidgin, etc. In the Whonix-Gateway distribution, you can find a set of server applications, including Apache httpd, nginx, and IRC servers, which can be used to organize the operation of hidden Tor services. Tunneling over Tor for Freenet, i2p, JonDonym, SSH, and VPNIf desired, the user can rely solely on Whonix-Gateway and connect their regular systems through it, including Windows, which allows for anonymous access for workstations already in use.

Key Changes:
- Updated builds based on the components of the secure distribution Kicksecure, which extends Debian with additional mechanisms and settings to enhance security: AppArmor for isolation, updating via Tor, use of the PAM module tally2 for protection against brute-force attacks, entropy extension for RNG, disabling suid, no open network ports by default, use of recommendations from the KSPP (Kernel Self Protection Project), and adding protection against information leakage about CPU activity, etc.
- The reliability of the proxy configuration has been improved in the anonymous connection wizard (anon-connection-wizard).
- By default, the installation of Mozilla Thunderbird has been discontinued due to changes in the usage conditions from Mozilla.
- The anon-gw-base-files package implements the automatic launch of the sysmaint panel (system management and administrative task execution) on Whonix-Gateway systems that do not use Qubes.
- The sysmaint panel has unnecessary buttons hidden and Tor management tools added for Whonix-Gateway.
- QEMU has been removed from the list of supported hypervisors in systemcheck.
- It is reported that Whonix 17.4 will likely be the last release based on Debian 12. The porting process to Debian 13 has already begun.
Source: opennet.ru
